Affichage des articles dont le libellé est Edward Snowden. Afficher tous les articles
Affichage des articles dont le libellé est Edward Snowden. Afficher tous les articles

Snowden Revealed Canada as a major Player in Running Electronic Spying

Former NSA contractor, Edward Snowden has revealed the top secret documents related to Canada’s ambition to become a major player in the world of electronic spying.

Canadian Broadcasting Corporation and The Intercept have published files which show that Canuck intelligence has developed its own technology to keep government servers secure. The EONBLUE system uses a mix of malware signatures and heuristics to identify network threats and maintain communications security.

Edward Snowden says Canada involed in spying


However the documents have also presented disclosures about the Canadians’ capability to disable, control or destroy an enemy's internet-connected infrastructure using software tools. Furthermore the Communications Security Establishment (CSE) reported that it has the ability to carry out "false flag" activities, making attacks look like someone else is accountable in "creating unrest."

The documents have also revealed that the NSA and its northern counterpart "cooperate closely" in "computer network access and exploitation" of certain international targets. According to one document, in April 2013, NSA targets are located in the Middle East, North Africa, Europe and Mexico, in addition to unnamed countries probably connected to the two agencies' counterterrorism goals.

An April 2013 memo [PDF] describes that how the CSE and NSA have been formally working together since 1949, and in 1986 signed an "Information Assurance" (IA) agreement with the US on intelligence operations.

"Cooperation efforts include the exchange of liaison officers and integrates, joint projects, shared activities and a strong desire for closer collaboration in the area of cyber defense," the document reads. "Since Canada has a limited ability to produce cryptographic devices, it is a large consumer of US IA products."

Another document, a 2011 presentation by a CSE analyst, summarizes a broad array of Canadian cyber-spy capabilities. According to the CBC, most of these schemes are designed for hacking operations including: "destroying infrastructure, which could include electricity, transportation or banking systems; disrupting online traffic by such techniques as deleting emails, freezing internet connections, blocking websites and redirecting wire money transfers."

~ mercredi 25 mars 2015 0 commentaires

Edward Snowden Secret Talk with Tech Experts at SXSW

NSA whistleblower Edward Snowden came up via video call at the SXSW festival in Austin, Texas, on Sunday morning. Snowden held a streamed question-and-answer session with a group of invited privacy campaigners and technology experts.

Edward Snowden cannot attend tech conferences in person because he may be arrested if he leaves Russia. Sunday Yokubaitis, president of online privacy company Golden Frog, described as a "call to arms" that came in the form of a question and answer session.




The meeting was attended by Yokubaitis along with Cloudflare CEO Matthew Prince, Twitter senior product counsel Matthew Zimmerman, and Evernote CEO Phil Libin, and others.

As reported by Yokubaitis, Snowden said that companies need to adopt more secure technology that could brick surveillance in a mass or make it too stiff to pursue en masse. A major focus was end-to-end encryption, which means that the contents of communications would be visible to only the sender and the recipient. No third party can have access to the content which is being communicated.

"The low-hanging fruit is always [the] transit layer," Edward reported. "It raises the cost. Every time we raise the cost, we force budgetary constraints." This is especially relevant as tools that are built for targeted steadily grow into broader programs. "We hope that they start with North Korea and by the time they end up in Ohio, they run out of budget."

Edward Snowden described that security systems like SSL are critical infrastructure because enough investment has not been made on these systems and as a result they have been subject to vulnerabilities. He further elaborated that if encryption is not common, simply using will mark a message as suspicious. Therefore companies should work for better encryptions.

"Him saying validates that companies should try and fill the holes, and not wait for policy," said Yokubaitis after the meeting.

~ mardi 17 mars 2015 0 commentaires

NSA’s ‘MonsterMind’ Could Launch Cyber Counterattacks Against Hackers

http://www.ehacking.net/2014/08/nsas-monstermind-could-launch-cyber.html
As the story covered by infosecurity-magazine, A new cyber defense system being developed by the NSA could automatically launch counter-strikes against attackers who target the US, whistleblower Edward Snowden has claimed.

The MonsterMind project, still under development at the spy agency, features algorithms which would automatically scan vast chunks of metadata with the aim of picking out malicious traffic.


With that intelligence the NSA system could then neutralize the threat and even theoretically launch a retaliatory strike autonomously, Snowden told Wired.

However, such a capability could end up targeting the innocent compromised computers being used by an attacker as a botnet to launch the initial threat, the whistleblower cautioned.

“These attacks can be spoofed,” Snowden told the site.

“You could have someone sitting in China, for example, making it appear that one of these attacks is originating in Russia. And then we end up shooting back at a Russian hospital. What happens next?”

The second issue is that for the system to work effectively, the NSA would have to gain access to all communications traffic coming into the US. Seizing private comms without a warrant and with no suspicion of wrongdoing would violate the Fourth Amendment, Snowden added.

Sean Sullivan, security consultant at F-Secure, agreed that the MonsterMind may end up counter-attacking botnets comprised of compromised computers belonging to US citizens or allies of the States.

“Counterattack options are only useful if the adversary has something to lose. Take North Korea as an example,” he continued.

“It might attempt to launch an attack from comprised resources. But even if it used its own servers to attack US infrastructure – what besides those servers is there to counterattack? North Korea isn’t wired – it basically has nothing to lose.”

Sullivan labelled it an “overly complicated defense strategy”.

“A fraction of the money used by ‘MonsterMind’ could be spend on bug hunting and eliminating vulnerabilities to achieve greater results,” he told Infosecurity.
 

~ dimanche 17 août 2014 0 commentaires